Re: [OAUTH-WG] OAuth2 attack surface....

"Richer, Justin P." <jricher@mitre.org> Mon, 25 February 2013 22:58 UTC

Return-Path: <jricher@mitre.org>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4557A21E8140 for <oauth@ietfa.amsl.com>; Mon, 25 Feb 2013 14:58:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.576
X-Spam-Level:
X-Spam-Status: No, score=-6.576 tagged_above=-999 required=5 tests=[AWL=0.022, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mbcv2-ipsCjx for <oauth@ietfa.amsl.com>; Mon, 25 Feb 2013 14:58:49 -0800 (PST)
Received: from smtpksrv1.mitre.org (smtpksrv1.mitre.org [198.49.146.77]) by ietfa.amsl.com (Postfix) with ESMTP id 63A6321E80FE for <oauth@ietf.org>; Mon, 25 Feb 2013 14:58:49 -0800 (PST)
Received: from smtpksrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id B4F97531022A; Mon, 25 Feb 2013 17:58:48 -0500 (EST)
Received: from IMCCAS01.MITRE.ORG (imccas01.mitre.org [129.83.29.78]) by smtpksrv1.mitre.org (Postfix) with ESMTP id A4402531022B; Mon, 25 Feb 2013 17:58:48 -0500 (EST)
Received: from IMCMBX01.MITRE.ORG ([169.254.1.25]) by IMCCAS01.MITRE.ORG ([129.83.29.68]) with mapi id 14.02.0318.004; Mon, 25 Feb 2013 17:58:48 -0500
From: "Richer, Justin P." <jricher@mitre.org>
To: William Mills <wmills_92105@yahoo.com>
Thread-Topic: [OAUTH-WG] OAuth2 attack surface....
Thread-Index: AQHOE6ur3a6hedYEIU2GnoIHTEpY3A==
Date: Mon, 25 Feb 2013 22:58:48 +0000
Message-ID: <B33BFB58CCC8BE4998958016839DE27E068A104F@IMCMBX01.MITRE.ORG>
References: <1361830944.13340.YahooMailNeo@web31812.mail.mud.yahoo.com> <E4A6D91D-2BC8-4F2E-9B1C-D1362A0E3608@oracle.com> <1361831644.50183.YahooMailNeo@web31801.mail.mud.yahoo.com> <1361832133.97884.YahooMailNeo@web31816.mail.mud.yahoo.com>
In-Reply-To: <1361832133.97884.YahooMailNeo@web31816.mail.mud.yahoo.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [172.31.18.27]
Content-Type: multipart/alternative; boundary="_000_B33BFB58CCC8BE4998958016839DE27E068A104FIMCMBX01MITREOR_"
MIME-Version: 1.0
Cc: O Auth WG <oauth@ietf.org>
Subject: Re: [OAUTH-WG] OAuth2 attack surface....
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Feb 2013 22:58:50 -0000

>From my read, it's a combination of browser bugs (it only affects Chrome) and Facebook's insistence on using the Implicit flow for everything.

While I don't at all care for the "sky is falling" rhetoric that seems to follow OAuth2, the author has some good suggestions for implementations: binding redirect URIs to particular flows, preference for the code flow, not using a default redirect_uri on a hosted domain with user-generated content.

But all of these are implementation issues that the OAuth2 protocol can't really address directly.

-- Justin


On Feb 25, 2013, at 5:42 PM, William Mills <wmills_92105@yahoo.com<mailto:wmills_92105@yahoo.com>> wrote:



DOH!!!  http://homakov.blogspot.co.uk/2013/02/hacking-facebook-with-oauth2-and-chrome.html

________________________________
From: Phil Hunt <phil.hunt@oracle.com<mailto:phil.hunt@oracle.com>>
To: William Mills <wmills_92105@yahoo.com<mailto:wmills_92105@yahoo.com>>
Sent: Monday, February 25, 2013 2:28 PM
Subject: Re: [OAUTH-WG] OAuth2 attack surface....

Whats the link?

Phil

Sent from my phone.

On 2013-02-25, at 14:22, William Mills <wmills_92105@yahoo.com<mailto:wmills_92105@yahoo.com>> wrote:

I think this is worth a read, I don't have time to dive into this :(
_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth




_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth